Session and Application variables in Asp.net core in case we use JWT tokens (So no cookie based sessions)

Viewed 433

We are using JWT token authentication generated from IdentityServer. I wonder what is the proper way to do the same functionality of sessions variables (and Application wide variables) when calling various controller actions. Should I store those variables in an InMemory cache for example ?

For example: I'm doing file upload to a controller action, I need some other controller action to report how much of that file was uploaded, so these two actions needs to have a common variable to report that file upload progress ...

Thank you ...

1 Answers

Application Session and Authentication Session are separate concepts. Application session is still viable for this scenario. However, you need to make sure that session cookie is sent in a response prior to the upload request so that the upload and status requests can be correctly associated. You'd also have to regularly commit the session state so the status request could read it, they don't share a live copy of the same data.

Or you use memory cache and give each upload a unique id (prior to the upload). That's almost identical to how session works.

Related